Skip to main content

Security & Compliance

What we protect, how, and — just as usefully for your review — what we do not have yet.

PearlAudit analyzes public government records. The property data in every dossier is public record, identical for every customer, and holds no personal information about you. The data worth protecting here is your account’s own activity — what your team searched, generated and downloaded, your API keys, and your branding. That is what the controls below are about.

Encryption & transport

All traffic is served over TLS 1.3. The application sends HSTS (two years, including subdomains, preload-eligible), an enforced Content-Security-Policy, X-Frame-Options: DENY plus frame-ancestors ‘none’, nosniff, a strict-origin referrer policy, and a Permissions-Policy that denies camera, microphone, geolocation and topics. These are response headers — you can verify every one of them against the live site before you believe this page.

API keys

Stored hashed

Keys are held as a hash, not as recoverable text. The full key is shown once, at creation, and cannot be retrieved afterwards — if it is lost, the path forward is to revoke and reissue.

Bound to the issuing account

Every key carries its owner and that account’s tier. The tier bounds what the key can reach and how much of it; a per-minute rate budget bounds how fast.

Revocable immediately

Revocation takes effect on the next request. Revoked keys keep their record so the audit trail of what that key did stays intact.

What keys do NOT have

There are no per-endpoint scopes. A key is limited by its tier and its owner, not by a grant list. If your integration needs a read-only or endpoint-restricted credential, say so during scoping — today the honest answer is that we would be building it for you.

Network & administrative surface

The public API is served through an explicit path allowlist at the edge: a route that is not on the list is not reachable from the internet, and administrative endpoints are not on the list. Outbound webhooks are HMAC-signed so your receiver can verify that a delivery came from us and was not altered in transit. The public lead forms are screened before anything is forwarded — a honeypot field, a time-to-submit check, and per-IP throttling.

Audit logging

Every search, dossier generation and download is timestamped and logged against the account that performed it, including through the API. That record is what lets a reviewer reconstruct what was checked on a deal and when.

The limit, stated plainly: attribution today is per account, not per analyst, because an account is currently a single login (see below). A firm sharing one login gets a complete record of what the firm did and no way to tell which analyst did it.

Data isolation & access

The property intelligence is public, read-only government data — the same corpus for every customer, so there is no per-customer property data to leak between accounts. Private account state — search and download history, API keys, watchlists, branding — is access-controlled and scoped to the account that owns it.

Access to production systems is restricted to PearlAudit personnel on a need-to-know basis. We do not grant third-party vendors direct access to your account data.

Retention & deletion

Account information and usage logs are retained for the life of the account and for up to three years after closure, to support billing disputes, legal compliance and audit requirements. You may request deletion of your account and its data at any time; we process deletion requests within 30 days, subject to legal retention obligations. Full detail is in the privacy policy.

Subprocessors

We use a deliberately small number of service providers, each under contract and permitted to use data only to perform services for us: authentication and session management, product analytics, payment processing, and — only when you order a printed briefing — physical mail delivery, which receives the delivery address you supply and nothing else. Municipal and federal data sources receive no personal data at all; we read public records from them.

We publish these by function rather than by vendor name. The named list, with roles and locations, goes to you as part of a security review or under NDA — ask and you will have it.

We do not use Google Analytics, Meta Pixel, or any third-party advertising tracker, and we do not sell your data.

What we do not have yet

No SOC 2 or ISO 27001

We hold neither certification today. We complete vendor security questionnaires and sign a DPA on request, and we would rather tell you this on our own page than have you find it in week three.

No SSO, no per-analyst seats

An account is a single login. There are no organizations, member roles, or SAML/OIDC enterprise connections yet, which is also why audit attribution stops at the account. This is the next thing we are building on the account layer; if a contract depends on it, raise it during scoping and we will give you a date.

No penetration-test report to share

We have no third-party penetration test to hand you. If your process requires one, tell us — it is a scoping conversation, not a brush-off.

No uptime SLA by default

Self-serve plans carry no contractual uptime or support SLA. Availability commitments are negotiated as contract terms on an enterprise agreement; current operational state is on the status page.

Reporting a vulnerability

If you believe you have found a security issue, email help@getpearlaudit.com with enough detail to reproduce it. We will acknowledge you, we will not pursue anyone who reports in good faith and does not exfiltrate data or degrade the service for others, and we will tell you when it is fixed.

Running a vendor review?

Send us your questionnaire and your DPA. We answer them ourselves, and we answer the awkward questions the same way this page does.

Start an enterprise conversation